Malware

Symmi.20120 (file analysis)

Malware Removal

The Symmi.20120 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Symmi.20120 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Symmi.20120?


File Info:

name: 0CBF0DE3CEBB146254B7.mlw
path: /opt/CAPEv2/storage/binaries/9f797df8d97165503f2fd661a496cda62f7d8a99c5566520566ad630e004be36
crc32: 744042A6
md5: 0cbf0de3cebb146254b75de2bf76159d
sha1: 42c9232d77eadf9aec5d167c1de2dae1d2d36089
sha256: 9f797df8d97165503f2fd661a496cda62f7d8a99c5566520566ad630e004be36
sha512: 3fa6622b92c9c6c36e6bc63928319aa5b1d0e9ee016f5212bb2fae099b07f5582325ae4849fbf150501018568a5eed61d42599d322cd4b50a4c7175107517127
ssdeep: 6144:OsTFCZX7KBGYd3BHn8h9EHkKykckkJw8+QkRhoT2Oa0O:OsToZX7KGY/pkd3kkitQS51T
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T182F4AF0B765DBA31F07A223300A94B278B29B92537330ACFBF85277556173C58F6671A
sha3_384: 4fef1836e8e2de32420d8aa8c36f2f90eefa684c5614aecdd9d270dfb588a755182c49e8d1abaf26247bb6689cf96c4f
ep_bytes: e85b8f0000e989feffffb8e0884100c3
timestamp: 2013-04-01 00:05:36

Version Info:

0: [No Data]

Symmi.20120 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Symmi.20120
FireEyeGeneric.mg.0cbf0de3cebb1462
ALYacGen:Variant.Symmi.20120
MalwarebytesMalware.AI.2162374652
ZillyaTrojan.Mulo.Win32.1
CynetMalicious (score: 100)
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaAI:Packer.EC4DB8D620
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.AERC
APEXMalicious
ClamAVWin.Trojan.Vresmon-9828832-0
BitDefenderGen:Variant.Symmi.20120
NANO-AntivirusTrojan.Win32.Buzus.brmthr
SophosML/PE-A
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader8.39300
VIPREGen:Variant.Symmi.20120
McAfee-GW-EditionBehavesLike.Win32.Generic.bt
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Symmi.20120 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Mulo.d
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Unknown
XcitiumTrojWare.Win32.Injector.AFSS@4wik6f
ArcabitTrojan.Symmi.D4E98
GoogleDetected
VBA32BScope.Trojan.Agent
MAXmalware (ai score=87)
Cylanceunsafe
IkarusVirus.Win32.CeeInject
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.ZVR!tr
Cybereasonmalicious.3cebb1
DeepInstinctMALICIOUS

How to remove Symmi.20120?

Symmi.20120 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment